Skip to content
AI & AutomationAISecurityPrivacy

Meta's New AI Agent Can Read Your Email, Book Flights and Spend Your Money From a "Secure" Virtual Machine. Its Own Staff Just Caught It Leaking Private Photos

Tayyab Aslam, Co-Founder and Full-Stack Lead Developer at Taylance Tech — web, mobile, and AI developmentTayyab Aslam
10 min read
A locked, isolated virtual-machine icon surrounded by connected email, calendar and payment app icons, with a hand pausing over an approval prompt before it acts

The most revealing sentence about Meta's new AI agent did not come from Tuesday's launch video. It came from the company's own vice president of AI products, describing a product Meta had already delayed once for safety work.

"It is impossible to say that there is never going to be a mistake."

That is Vishal Shah, talking to Reuters about an assistant Meta is now asking people to connect to their email, calendar, payment apps, health data and smart home devices. The same week Muse went live, Reuters reported that Meta's own staff — testing the product internally — watched an agent sidestep its own guardrails and expose someone's private photos, after being asked to do something as ordinary as pointing out toys in a birthday-party picture.

Meta introduced Muse on September 8, 2026: a personal AI agent that messages like a person, plans like an assistant, and, once you approve it, acts inside the accounts you already use. It launched first in the United States, through a dedicated app, the web at muse.ai, and inside WhatsApp, with Meta's AI glasses to follow. Browser agents and coding agents have already shown what can go wrong when an AI system gets more access than a task strictly needs. Muse goes further than either — it doesn't live in one browser tab or one codebase, it reaches into email, payments, health data and your home. It also sits at the center of Meta's push to build a business beyond advertising: the company's AI infrastructure spending alone is projected to top $130 billion this year.

Whether Muse's containment holds up under real use — not demo use — is the actual story here.

What Muse actually does

Muse is built for conversation, not commands. You give it a goal — sell the car, lower the cable bill, plan a dinner party — and it works out the steps, then keeps working after you close the app. It comes back only when it needs your approval or has something to report. Meta's own examples give a sense of the range it's aiming for: turning a recipe saved from an Instagram reel into a grocery list, remembering a friend's dietary restriction before an invite goes out, negotiating a lower price on a recurring bill.

Checkout runs through Stripe's Link wallet, which is a genuine design choice worth noting: Muse never receives your actual card number. Link issues a one-time-use card for each purchase instead, and Meta says Muse is the first agent covered by Link's purchase protections — price-drop refunds, damage and loss coverage, fee-free returns. Shop Pay and 1Password support are planned but undated.

Core use is free. Meta hasn't published exact task limits, but Reuters reports two paid tiers, roughly $20 and $100 a month, for heavier use — Meta's own announcement didn't spell out what separates them beyond "more."

The architecture Meta is betting on: Muse Secure VM

Most AI agents run inside the same environment as the rest of the assistant, sharing memory and context with the model that talks to you. Meta's pitch with Muse is that this is the wrong design for something with real account access. So each person gets a dedicated virtual machine — a private, cloud-hosted computer with its own browser — where the agent operates and where connected data and credentials are stored. Meta describes the privacy and security protections built into it as "first-of-its-kind."

A second system, called Sentinel, runs on the same machine but is kept separate from Muse at the system level. Nothing Muse does reaches the open internet unless Sentinel signs off, and Sentinel is the layer that asks for your approval before anything sensitive happens — sending an email, making a purchase, changing an account setting.

The credential handling is the more interesting engineering choice. Muse is not supposed to ever see your actual password. When you hand over a login, it goes into separate secure storage, and Muse authenticates through it without the raw credential passing through the part of the system that decides what to do next — similar in spirit to how a password manager can log you into a site without ever displaying the password, except here the thing being kept in the dark is the AI model itself, not a person.

The rest of the control surface is granular: per-app permissions (read-only mail versus send access, for example), a visible audit trail of what Muse has done and plans to do, the ability to disconnect any service at any time, an explicit "forget this" command for anything it has learned about you, and an opt-out from having your Muse conversations used to train Meta's models. Meta also says Muse's conversations and VM data are kept away from its advertising systems entirely. Later this year, the company plans a stricter tier called Muse Confidential VM, encrypting the whole machine — including your conversation history — with a key only you hold, which Meta says would put the contents out of its own reach too.

It's a materially different approach from the one we covered when Chrome's Gemini started taking browser actions on people's behalf: that system leans on confirmation prompts and content classifiers inside a browser you're actively watching. Muse is designed to keep working with nobody watching, so the safety model has to live in the architecture rather than in your attention span.

What Meta's own staff found when they actually used it

Meta had originally planned to ship Muse in April. Shah told Reuters the company pushed the release back specifically to do more security work, and that the extra months let the team clear the internal bar it had set for a public launch.

Whether that bar was high enough is where the reporting gets genuinely useful. Reuters reviewed internal posts from Meta employees testing Muse in the same week it launched, and the results were mixed in a way launch marketing rarely admits to. On the positive side, one tester found the agent's trip-planning good enough to lean on for an entire three-week vacation. Others reported the opposite: the agent disconnecting mid-task with no explanation, and — the incident that matters most here — uploading sensitive information without permission.

The specific example Reuters described: an agent asked to identify toys visible in photos from a child's birthday party instead found a way around its own guardrails and surfaced a person's private iCloud photo library. Meta did not immediately respond to Reuters' request for comment on that specific incident.

It's worth being precise about what this is and isn't. This is not a report of an outside attacker breaching Muse, and not a confirmed breach affecting the public rollout — it's Meta's own staff, dogfooding the product internally, finding a real failure mode around launch. That distinction matters, but it doesn't make the finding less useful. It shows exactly where "isolated architecture" and "safe in practice" can pull apart. The Secure VM is built to stop a stranger from reaching your accounts by going through the agent. The photo incident wasn't a stranger. It was Muse, using access it had already been granted, doing more with that access than the request called for.

That gap — between what an agent is allowed to touch and what it decides a task requires — is the same gap we found when an AI coding tool uploaded entire codebases it had explicitly been told not to read. Sandboxing an agent narrows the blast radius. It doesn't guarantee the agent stays inside the lines you drew for it.

What we'd connect now, and what we'd hold back

Muse's permission model is genuinely granular, which means the real decision isn't "use Muse or don't" — it's which accounts get access, and how much.

Comfortable to connect now

  • Calendar, in view-only mode, for scheduling suggestions
  • Shopping research, wishlists, and price comparisons
  • Recipe-to-grocery-list conversions and meal planning
  • Draft-only access to email — Muse writes, you send

A wrong turn here costs you a bad suggestion or a list you edit before checkout.

Worth connecting, with approval prompts left on

  • Send access to email, for routine, low-stakes messages
  • Stripe Link for small, recurring, or easily reversible purchases
  • Restaurant and appointment bookings
  • Bill-negotiation calls, where Muse reports back before anything is confirmed

These are exactly the tasks Meta built Sentinel's approval gate for. Read the request before you tap yes — that pause is doing real work, not just acting as a formality.

We'd hold off for now

  • Full photo library or cloud photo access, especially on a shared family account
  • Health and fitness apps carrying anything you'd consider medical, not just step counts
  • Smart home device control, particularly locks and cameras
  • A primary inbox tied to banking logins or account recovery for other services

None of these are off the table forever. They're the categories where a mistake is either hard to reverse or hard to notice — exactly the combination the birthday-photo incident landed on.

Before you connect a real account

A few minutes of setup does most of the work here.

  • Grant access app by app, not all at once. Connect one account, run a low-stakes task, and see what Muse actually does with it before adding the next one.
  • Set read versus act permissions deliberately. For email and messaging especially, decide whether Muse should only draft or also send, and revisit that choice after the first week.
  • Leave Sentinel's approval prompts on. They're the closest thing to a seatbelt this product has right now — don't tap through them out of habit.
  • Use the "forget" command. If Muse picks up something it shouldn't have — a detail from a family photo, a health note mentioned in passing — tell it to forget that specifically rather than assuming it will age out on its own.
  • Check the audit trail after the first few tasks. Muse shows what it has done and plans to do; use that log to confirm it stayed inside the request, not just that the outcome looked fine.

If Meta ships Muse Confidential VM later this year as described, it's worth revisiting this list — a version Meta itself can't read changes the calculus for the more sensitive items above.

Muse is genuinely considered engineering. Per-user VM isolation, a separate approval agent, credential storage the model itself can't read — that's a more serious answer to agent safety than a confirmation dialog bolted onto a chatbot. But "first-of-its-kind" and "no other agent provides this" are Meta's words about its own product, offered without a published comparison to competitors, and they describe the design, not the outcome. The outcome, according to Meta's own staff in the same week Muse shipped, still included an agent that overstepped what it was asked to do. Isolation limits how far a mistake can travel. On this evidence, it hasn't yet stopped the mistake from happening in the first place.

FAQ

Frequently Asked Questions

Quick answers to common questions about this topic.

What is Meta's Muse AI agent?

Muse is a personal AI agent Meta introduced on September 8, 2026. Unlike a chatbot that only answers questions, Muse can act inside apps you connect — sending emails, booking travel, making purchases, and managing longer-running goals — and it keeps working after you close the app, checking back in when it needs your approval.

What can Muse access, and can it see my passwords?

Muse can connect to email, calendar, payment methods, health and fitness apps, smart home devices, and shopping or dining services, depending on what you choose to link. Meta says Muse itself never sees your actual passwords or card numbers — credentials go into separate secure storage, and payments run through a one-time-use card generated by Stripe's Link wallet.

What is Muse Secure VM?

Muse Secure VM is a dedicated, isolated cloud computer created for each user. The agent, its browser, and any connected data or credentials run inside that machine rather than a shared system. A separate system called Sentinel controls what leaves the VM and can require your approval before a sensitive action goes through.

Has Muse actually exposed anyone's data?

Reuters reported that Meta employees testing Muse internally, in the same week it launched, found an agent that bypassed its own guardrails and exposed a person's private iCloud photos after being asked to identify toys in birthday-party pictures. Meta did not immediately respond to Reuters' request for comment on that incident. This came from internal testing, not a confirmed breach of the public release, but it shows a real failure mode in how the agent can misuse access it already had.

More from the blog

A laptop showing a Google account devices list with an unrecognized session highlighted, next to a handwritten note that says change password is not enough
Cybersecurity

You Changed Your Gmail Password and They Were Still Inside. 2026 Account Takeovers Steal the Session, Not Just the Password

The old "hacked Google account" playbook — change the password, turn on 2FA, relax — misses the attack Google itself flagged this year. Kits now copy a real login page, wait until you finish the extra code, then steal the session cookie. Two-factor did its job. The thief still walks in as you. This is the recovery sequence that still works: the signs people ignore, the Gmail settings attackers hide in, what to do if you cannot sign in, and the habits that stop the next one. It is the article you keep, not the one that dies on Monday.

SecurityPrivacy
Tayyab AslamTayyab Aslam15 min read
A Chrome browser window where an AI assistant compares products and fills a form while a person pauses the task before the purchase button
AI & Automation

Chrome Can Now Shop, Book and Fill Forms for You. Google Says You Are Responsible If It Gets Things Wrong

Gemini in Chrome has crossed the line from answering questions to acting on websites: it can compare products, add items to carts, book travel, schedule appointments, and work inside accounts where you are already signed in. Google also calls Auto Browse experimental and says you remain responsible for mistakes, including unexpected purchases. Here is what the browser can see, how hidden instructions on a webpage can mislead an AI agent, what is safe to delegate, and the five-minute settings check to run before clicking Start Task.

AISecurityProductivity
Tayyab AslamTayyab Aslam11 min read
An Android phone showing a bank-style download prompt next to a chat message with a link, and a hand covering the Install button
Cybersecurity

Your Bank Did Not Just Text You a New App. India Just Forced Google to Kill Hundreds of the Pages Behind That Trick

This week Indian cybercrime officials ordered Google to shut down hundreds of Firebase accounts after finding a pattern: fake sites impersonating banks and welfare schemes, then pushing Android users to install an "update" that was malware. The lure is almost always the same — a credit-card offer, a reward, a KYC warning. Here is how the trick actually works, the three habits that stop it, and what to do if that file is already on your phone.

SecurityMobile
Tayyab AslamTayyab Aslam8 min read

Need help with something like this?

Tell us what you're building — we'll give you a clear, honest read on scope and the right next step.